Are you developing a chatbot in Switzerland that is also intended for European customers? Do you use an AI system to create an advertising campaign targeting the Italian market? Do you generate deepfakes or informational content, or use biometric categorisation tools during events in the European Union?
Being established in Switzerland is not sufficient to exclude the application of the AI Act.
As is already the case under the GDPR, the European legislature has established a territorial scope that may also extend to companies established in third countries. However, the criteria under the AI Act are specific: the placing of the system on the European market, its putting into service in the Union, and the use within the EU of outputs produced by the system are all relevant.
The Guidelines published by the European Commission on 20 July 2026 clarify how the transparency obligations under Article 50, applicable from 2 August 2026, must be implemented, clearly distinguishing between the roles of provider and deployer.
Why the AI Act may apply to a Swiss Company
Article 2 of the AI Act provides that the Regulation applies:
- to providers placing AI systems on the market or putting them into service in the Union, irrespective of where they are established;
- to providers and deployers established in a third country where the output produced by the AI system is used in the Union.
The purpose is to prevent the protection of persons located in the EU from being circumvented simply by developing or using the system from a country outside the European Union.
The assessment must therefore not be limited to the company’s registered office. It must also consider the target market, the audience reached, the distribution channels, and the specific intended use of the outputs.
The Swiss Company as a provider
A provider is a company that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. It is irrelevant whether the system is supplied free of charge or against payment.
A Swiss company will therefore be subject to Article 50 of the AI Act as a provider where, for example, it:
- markets a chatbot or virtual assistant to Italian or European customers;
- makes a platform that generates images, audio, video, or text available in the EU;
- develops a “Power AI” system for a corporate group and puts it into service at a subsidiary established in the Union;
- directly offers an AI application to European users under its own name or trademark.
In these cases, the existence of a European branch is not decisive: it is sufficient for the system to be placed on the market or put into service in the Union.
Obligations of the Swiss provider
The provider of a system intended to interact directly with natural persons must design the system so that users are informed that they are interacting with AI, unless the artificial nature of the interaction is obvious. The notice must be incorporated into the functioning of the system and cannot be confined exclusively to the general terms and conditions or technical documentation.
Example: a software company based in Lugano offers Italian businesses a customer-service chatbot. The system must clearly identify itself as an AI-based assistant, for example at the beginning of the conversation: “You are interacting with an artificial intelligence system.”
Providers of systems that generate or manipulate text, images, audio, or video must also ensure that the outputs are identifiable through machine-readable markings. As far as technically feasible, the technical solutions must be effective, interoperable, robust, and reliable.
Example: a Swiss company supplies an image-generation platform in the EU for the creation of advertising materials. It is not sufficient to allow the customer to add the words “created with AI” voluntarily: the system must incorporate a technical solution enabling the artificial origin of the output to be detected.
When European use is not sufficient
The Guidelines introduce an important reasonableness criterion. Where the system has neither been placed on the market nor put into service in the EU, European use that is merely occasional, unforeseeable, or unauthorised should not, in itself, result in the application of the obligations to the non-EU provider.
Example: a platform designed exclusively for the Swiss market is used by a customer, without authorisation, to produce content intended for Italy. Such isolated use should not automatically make the Swiss provider responsible under Article 50. The conclusion is different where the provider is aware of, permits, or systematically organises such European use.
The Swiss Company as a deployer
A deployer is a company that uses an AI system under its authority, deciding whether to use it, for which purposes, and how to use the system and its outputs. Technical control over the software is not required.
The company remains the deployer even when the system is actually used by employees, collaborators, freelancers, or suppliers acting on its behalf and under its responsibility. By contrast, a customer commissioning work from an agency is not normally the deployer where neither decides whether AI is used nor controls how the agency uses it.
For a Swiss company, the deployer obligations apply where the output is used within the Union and the company plans, directs, or authorises that use or dissemination.
Publication on the Internet may also be sufficient where the content is specifically intended for, or can reasonably be expected to reach, a European audience. By contrast, dissemination within the EU through unforeseeable channels outside the company’s control is not relevant.
Deepfake intended for the European market
A Swiss company uses a generative system to create a video in which a well-known spokesperson appears to make statements that were never actually made. The video is included in an advertising campaign also targeting Italy.
The company is the deployer because it determines the purpose and way the system is used and directs the dissemination of the output within the Union. It must therefore clearly and perceptibly disclose that the video has been artificially generated or manipulated.
Please note: the technical marking inserted by the provider does not replace the visible label intended for the public.
Biometric categorisation at a european event
A Swiss company participates in a trade fair in Milan and installs an AI-based camera at its stand that categorises visitors according to apparent age groups in order to measure the audience interested in its products.
The company must inform all exposed persons that a biometric categorisation system is operating in the area. In this case, the notice must be clearly visible no later than the time of first exposure.
Compliance with Article 50 does not remove the need to assess separately the lawfulness of the processing under the GDPR and other applicable legislation.
Public-interest text addressed to the EU
A Swiss publishing company uses AI to generate an analysis of the economic consequences of new European legislation and publishes it, without human review, on a website also aimed at Italian readers.
The text is published to inform an indeterminate audience about a matter of public interest. The company must therefore disclose that the content was generated or manipulated using AI.
The labelling requirement may be omitted only where the text has undergone substantial human review or effective editorial control and a natural or legal person assumes editorial responsibility for its publication.
When the Swiss Company performs both roles
Provider and deployer are not necessarily mutually exclusive categories. A company may perform both roles simultaneously.
Example: a company based in Lugano develops an in-house system capable of generating synthetic videos and uses it to produce a campaign targeting the Italian market. It will be:
- the provider of the system, with the obligation to implement technical marking and ensure that outputs are detectable;
- the deployer in relation to the campaign, with the obligation to place a clear and perceptible label on the deepfake.
The same organisation must therefore distinguish between obligations relating to the design of the system and those relating to its specific use.
Relationship with Swiss legislation
The application of the AI Act does not exclude the application of the Swiss Federal Act on Data Protection. The Federal Data Protection and Information Commissioner has clarified that the FADP, which is drafted in technologically neutral terms, applies directly to processing activities supported by AI.
According to the Swiss authority, manufacturers, providers, and users must ensure transparency regarding the purpose, functioning, and sources of the data used. Users must also be able to understand when they are communicating with a machine, and the use of programs that manipulate the faces, images, or voices of identifiable persons must be clearly disclosed.
A Swiss company may therefore be required to comply simultaneously with:
- Article 50 of the AI Act, due to its connection with the Union market or audience;
- the Swiss FADP, where personal data are processed;
- the GDPR, where its respective territorial criteria are independently met;
- legislation concerning copyright, image rights, voice rights, advertising, and consumer protection.
Providing information about the artificial origin of the system or content does not render lawful a use that is prohibited or lacks an adequate legal basis.
Operational assessment for Swiss Companies
Before 2 August 2026, a Swiss company should answer at least the following questions:
- Is the company a provider, a deployer, or does it perform both roles?
- Is the system offered, marketed, or put into service in the Union?
- Are the outputs intended for, used in, or foreseeably disseminated within the EU?
- Is the European use decided, authorised, or controlled by the company?
- Does the use involve direct interaction, generative content, deepfakes, biometrics, or public-interest text?
- Is the information clear, distinguishable, accessible, and provided at the time of the first interaction or exposure?
Main sources: Regulation (EU) 2024/1689, Articles 2, 3, and 50; European Commission, Guidelines on Article 50 of 20 July 2026; European Commission FAQs on transparency obligations; FDPIC, AI and Data Protection.



